10 Best Cloud Penetration Testing Companies in 2026
Updated:
August 10, 2026
Cloud penetration testing finds exploitable weaknesses in cloud identities, configurations, storage, APIs, workloads, containers, and networks before attackers can use them. Traditional network testing alone does not cover risks such as excessive IAM permissions, exposed storage, insecure service relationships, and privilege-escalation paths.
The strongest providers combine cloud-platform expertise with manual exploitation across AWS, Microsoft Azure, Google Cloud, Kubernetes, serverless systems, and infrastructure as code.
This guide compares 10 companies by technical coverage, delivery model, pricing approach, remediation support, certifications, and organizational fit.
| Company | Cloud Platforms Supported | Kubernetes and Container Testing | Best For | Pricing Model |
|---|---|---|---|---|
| Bright Defense | AWS, Azure, Google Cloud | Confirm container scope during scoping | Startups, SaaS, SMBs, regulated teams | Published plans with custom cloud scope |
| Bishop Fox | AWS, Azure, Google Cloud | Kubernetes testing available | Complex enterprise IAM and attack paths | Custom objective-based engagement |
| Rhino Security Labs | AWS, Azure, Google Cloud | Confirm container scope during scoping | Deep AWS IAM and post-exploitation | Custom project |
| NetSPI | AWS, Azure, Google Cloud | Container and Kubernetes coverage | Enterprise recurring and continuous testing | Custom PTaaS or project |
| Cobalt | AWS, Azure, Google Cloud, hybrid | Container hardening available | Fast recurring release-driven testing | Annual credit packages |
| Praetorian | AWS, Azure, Google Cloud, hybrid | Kubernetes and container testing | Complex attack paths, CI/CD, serverless | Custom project or continuous program |
| TrustedSec | AWS and Azure | Confirm exact scope during scoping | Assumed access and Microsoft identity | Custom consulting |
| Coalfire | Major public cloud and hybrid environments | Confirm exact scope during scoping | Compliance, FedRAMP, regulated cloud | Custom project or OnDemand |
| IBM X-Force Red | Cloud and hybrid environments | Confirm exact scope during scoping | Global hybrid offensive programs | Project, subscription, or managed |
| Mandiant | AWS, Azure, Google Cloud, multi-cloud | Confirm exact scope during scoping | Threat intelligence and response validation | Custom project or retainer |
How We Selected These Companies
Each provider was assessed against six weighted criteria designed to distinguish cloud-native offensive testing from general penetration testing.
| Selection Criterion | Weight |
|---|---|
| Cloud-Native Testing Depth | 30% |
| Platform And Workload Coverage | 20% |
| Manual Exploitation And Attack-Path Validation | 15% |
| Reporting, Remediation, And Retesting | 15% |
| Delivery Model And Organizational Fit | 10% |
| Pricing Transparency And Procurement Flexibility | 10% |
Broader penetration testing statistics show why manual exploitation depth carries the heaviest weight of the six.
10 Best Cloud Penetration Testing Companies in 2026
So, here are the 10 best cloud penetration testing companies to consider in 2026. The list is presented in random order, and placement does not indicate that one company is superior to another. Each company included here is a legitimate provider with an established market presence and a solid customer profile.
Here are the companies that made the list:
1. Bright Defense
Bright Defense is a Culver City cybersecurity firm founded in 2023 by Tim Mektrakarn and John Minnix. It provides cloud, web application, API, and network penetration testing alongside vulnerability management, continuous compliance, and vCISO services.
Cloud testing covers AWS, Microsoft Azure, and Google Cloud, with attention to identities, permissions, storage, applications, workloads, exposed services, and privilege-escalation paths.
Best For
Best suited to startups, SaaS companies, SMBs, and regulated organizations that want cloud testing connected to remediation and frameworks such as SOC 2, ISO 27001, HIPAA, PCI DSS, CMMC, and NIST.

Company Overview
- Company Name: Bright Defense, LLC
- Headquarters: Culver City, California, United States
- Founded: 2023
- Founders: Tim Mektrakarn and John Minnix
- Service Coverage: United States
- Supported Cloud Platforms: AWS, Microsoft Azure, and Google Cloud
- Core Services: Cloud, web application, API, and network penetration testing; continuous compliance; vulnerability management; vCISO services
- Compliance Frameworks: SOC 2, ISO 27001, HIPAA, PCI DSS, CMMC, and NIST
- Certification: ISO 27001:2022 certified
- Partnership: Drata Gold Partner
- Delivery Model: Consultant-led testing with remediation and retesting support
- Published Penetration Testing Pricing: $2,750 to $9,250
- Website: brightdefense.com
Cloud Penetration Testing Capabilities
Bright Defense reviews IAM users, service accounts, roles, policies, trust relationships, and credentials for excessive access and privilege-escalation opportunities.
Testing can cover storage, databases, backups, virtual networks, security groups, exposed services, applications, APIs, serverless functions, workloads, and secrets.
Consultants validate whether a compromised identity, application, or workload could reach sensitive systems or data.
Key Features
- Human-Led Testing: Combines automated discovery with manual exploit validation.
- Multi-Cloud Coverage: Tests AWS, Microsoft Azure, and Google Cloud.
- Audit-Ready Reporting: Provides evidence, risk ratings, technical impact, and remediation guidance.
- Remediation and Retesting: Supports corrective work and validation after fixes are applied.
- Compliance Integration: Connects findings to SOC 2, ISO 27001, HIPAA, PCI DSS, CMMC, and NIST.
Compliance Support
Findings can support SOC 2, ISO 27001, HIPAA, and PCI DSS programs, plus CMMC and NIST requirements, through validated evidence, remediation guidance, and retesting. SOC 2 penetration testing covers how auditors treat cloud test evidence against the Trust Services Criteria.
Pros
- Tests AWS, Microsoft Azure, and Google Cloud
- Strong fit for startups, SaaS companies, and SMBs
- Connects penetration testing with compliance support
- Provides human-led validation and practical remediation guidance
- Includes retesting and audit-ready reporting
- Publishes standard penetration testing prices
Limitations
- United States-focused delivery may not suit programs requiring large in-country teams across several regions.
Pricing
Bright Defense publishes three standard penetration testing plans:
| Plan | Testing Hours | Published Price |
| Ignite | 48 hours | $2,750 |
| Elevate | 96 hours | $5,250 |
| Summit | 176 hours | $9,250 |
Cloud pricing varies with account count, IAM complexity, and application scope. Kubernetes coverage, access model, compliance requirements, and retesting can increase the testing effort.
Customer Evidence
Customer feedback highlights responsive communication, clear reporting, practical remediation guidance, and reliable delivery, including engagements supporting SOC 2 objectives.
2. Bishop Fox
Bishop Fox is a Tempe-based offensive security company founded in 2005 by Vincent Liu and Francis Brown. Its services cover cloud, application, network, hardware, AI, red teaming, and continuous exposure assessments.
Cloud testing covers AWS, Microsoft Azure, Google Cloud, and Kubernetes. It combines configuration analysis with manual testing of identity, trust, and service relationships.
Best For
Best suited to enterprises, cloud-native companies, and regulated organizations that need advanced IAM testing, cross-account attack simulation, Kubernetes assessment, infrastructure-as-code review, or detection validation.

Company Overview
- Company Name: Bishop Fox, LLC
- Headquarters: Tempe, Arizona, United States
- Founded: 2005
- Founders: Vincent Liu and Francis Brown
- Supported Environments: AWS, Microsoft Azure, Google Cloud Platform, and Kubernetes
- Customers Protected: 1,500+
- Core Services: Cloud, application, network, mobile, hardware, and AI penetration testing; red teaming; social engineering; continuous exposure management
- Corporate Assurance: ISO/IEC 27001 certification and SOC 2 Type 2 assurance
- Delivery Model: Consultant-led, objective-based offensive security testing
- Pricing: Custom quote
Cloud Penetration Testing Capabilities
Bishop Fox reviews identities, roles, service accounts, policies, credentials, permission boundaries, and trust relationships for privilege-escalation paths.
Testing covers movement across AWS accounts, Azure subscriptions, Google Cloud projects, applications, storage, networks, deployment systems, and sensitive data.
Their objective-based engagements target agreed outcomes such as gaining privileged credentials, crossing account boundaries, or accessing sensitive data.
Key Features
- Manual Attack-Path Testing: Connects identity and configuration weaknesses into practical exploit chains.
- Multi-Cloud Coverage: Supports AWS, Azure, Google Cloud, and Kubernetes.
- IAM Expertise: Tests privilege escalation, cross-account trust, and service-role permissions.
- Original Cloud Tooling: Develops CloudFox and Cirro for cloud attack-path mapping.
- Detection Validation: Tests whether simulated attacks generate useful alerts.
Pros
- Long offensive security track record
- Supports AWS, Azure, Google Cloud, and Kubernetes
- Strong IAM and privilege-escalation testing
- Combines configuration review with manual exploitation
- Develops original cloud security tools
- Experienced with complex enterprise environments
Limitations
- Objective-based engagements focus on agreed attack goals, so areas outside those goals may receive less attention.
- CloudFox and Cirro provide different platform coverage.
- The service focuses on offensive validation rather than full compliance-program implementation.
Pricing
Bishop Fox provides custom quotes based on cloud platforms, account count, architecture complexity, applications, Kubernetes, testing objectives, duration, compliance needs, and retesting.
Customer Evidence
Bishop Fox reports protecting 1,500+ customers. Public examples include LastPass, where it tested AWS IAM, cross-account trust, Kubernetes, CI/CD, and alerting, and Reltio, where it assessed a cloud-native SaaS and Kubernetes environment.
3. Rhino Security Labs
Rhino Security Labs is a Seattle-based boutique security firm founded in 2013 by Benjamin Caudill. It provides cloud, network, web, mobile, code review, phishing, and red team assessments.
Its AWS, Microsoft Azure, and Google Cloud testing emphasizes manual, research-led exploitation of identity, configuration, storage, and post-compromise attack paths.
Best For
Best suited to cloud-native companies and security-mature organizations needing deep AWS and IAM analysis, post-exploitation testing, storage reviews, or independent validation before an audit or launch.

Company Overview
- Company Name: Rhino Security Labs, Inc.
- Headquarters: Seattle, Washington, United States
- Founded: 2013
- Founder and CEO: Benjamin Caudill
- Supported Cloud Platforms: AWS, Microsoft Azure, and Google Cloud Platform
- Core Services: Cloud, network, web and mobile application penetration testing; secure code review; phishing; vishing; red teaming
- Primary Industries: Technology, finance, healthcare, and retail
- Delivery Model: Consultant-led, manual deep-dive penetration testing
- Pricing: Custom quote
Cloud Penetration Testing Capabilities
Rhino performs authenticated assessments that test what an attacker could do with a compromised identity, including privilege escalation, persistence, lateral movement, data access, and defense evasion.
AWS work can cover IAM, EC2, S3, Lambda, CloudTrail, GuardDuty, security groups, and related services. Azure and Google Cloud engagements examine identities, workloads, networks, storage, and connected services.
Critical findings or signs of prior compromise are reported during the engagement, followed by detailed remediation guidance and retesting.
Key Features
- Manual Cloud Exploitation: Proves exploitability rather than returning configuration alerts alone.
- AWS Research Depth: Publishes practical research on IAM, Lambda, S3, CloudTrail, GuardDuty, and credential abuse.
- Pacu: Developed an open-source AWS exploitation framework for post-compromise testing.
- CloudGoat: Created vulnerable AWS scenarios for practicing realistic attack paths.
- Remediation Testing: Retests corrected findings and provides technical and executive reporting.
Pros
- Dedicated AWS, Azure, and Google Cloud services
- Strong AWS IAM and post-exploitation expertise
- Manual testing supported by original security research
- Developer of Pacu and CloudGoat
- Tests persistence, lateral movement, and defense evasion
- Provides remediation guidance and retesting
Limitations
- Its public research and tooling are most developed for AWS, with less public methodology detail for Azure and Google Cloud.
- Boutique staffing can require advance scheduling for simultaneous large or multi-region engagements.
- A continuously managed PTaaS portal is not a prominent part of the service model.
Pricing
Rhino Security Labs provides custom quotes based on the cloud provider, account count, services, IAM complexity, applications, access level, testing depth, schedule, and retesting requirements. Deep post-exploitation and multi-cloud scopes require more testing time than a configuration-focused assessment.
Customer Evidence
Rhino reports clients ranging from technology startups to large enterprises. Its Pacu and CloudGoat projects provide further evidence of its AWS specialization.
“ We would look at Rhino when AWS attack-path depth carries more weight than platform workflow features. Its public research and tooling show particularly strong AWS specialization.“
4. NetSPI
NetSPI is a Minneapolis-based offensive security company founded in 2001. Led by President and CEO Aaron Shilts, it provides cloud, application, network, red team, attack-surface, hardware, AI, and continuous testing services.
Its AWS, Microsoft Azure, and Google Cloud assessments combine manual exploitation, automation, proprietary tooling, purpose-built AI, and a Penetration Testing as a Service platform.
Best For
Best suited to large or regulated enterprises needing recurring cloud assessments, complex IAM testing, internal and external attack simulation, and real-time remediation management.

Company Overview
- Company Name: NetSPI
- Headquarters: Minneapolis, Minnesota, United States
- Founded: 2001
- Co-Founder and Chairman: Deke George
- President and CEO: Aaron Shilts
- Geographic Presence: United States, Canada, United Kingdom, and India
- Supported Cloud Platforms: AWS, Microsoft Azure, and Google Cloud Platform
- Security Experts: 350+ in-house security experts
- Core Services: Cloud, application, API, network, AI, mainframe, hardware, IoT, and continuous penetration testing; red teaming; social engineering; attack surface management
- Delivery Model: Human-led, AI-accelerated Penetration Testing as a Service
- Procurement: Available through AWS Marketplace
- Pricing: Custom quote
Cloud Penetration Testing Capabilities
NetSPI tests from external and authenticated internal perspectives. Testers examine how identities, exposed services, applications, and workloads could form attack paths.
AWS, Azure, and Google Cloud assessments cover platform-specific IAM, storage, compute, and network controls. Testing can extend to containers, serverless services, key management, and service relationships.
The methodology starts with automated discovery and manual verification. Testers then examine privilege escalation, network pivoting, and access to sensitive systems or data. Testing references NIST SP 800-53, MITRE ATT&CK, and CIS benchmarks.
Key Features
- Human-Led Testing: Uses in-house specialists to validate vulnerabilities and investigate attack paths.
- Multi-Cloud Coverage: Provides dedicated AWS, Azure, and Google Cloud testing.
- Internal and External Perspectives: Simulates internet attackers and authenticated cloud users.
- PTaaS Platform: Supports tester communication, live findings, remediation tracking, and repeated tests.
- Continuous Cloud Testing: Provides recurring testing for rapidly changing environments.
- Resource-Level Findings: Links vulnerabilities directly to affected cloud resources.
Compliance Support
Validated findings, evidence, and remediation guidance can support SOC 2, PCI DSS, ISO 27001, HIPAA, NIST, MITRE ATT&CK, and CIS-based security programs.
Pros
- Long penetration-testing track record
- Supports AWS, Microsoft Azure, and Google Cloud
- Large in-house cloud and offensive security team
- Strong IAM and privilege-escalation testing
- Provides point-in-time and continuous assessments
- Offers real-time collaboration and remediation tracking
Limitations
- The full PTaaS value depends on integrating live findings, ticketing, and recurring remediation workflows into internal operations.
- Resource-level reporting can require substantial asset normalization in highly decentralized cloud estates.
- Its broad service catalog requires strict scope governance to keep multi-team programs manageable.
Pricing
NetSPI provides custom enterprise pricing based on cloud accounts, resources, identities, access perspectives, architecture, applications, containers, testing frequency, integrations, compliance needs, and retesting. Services are available directly or through AWS Marketplace, and continuous programs carry a different cost structure from point-in-time tests.
Customer Evidence
NetSPI lists major banks, healthcare organizations, technology companies, retailers, and large enterprises among its customers. Public references include Microsoft, Trimble, Nuspire, Gong, and Hudl.
“We see NetSPI as a stronger fit for organizations running repeated cloud assessments across many accounts or business units. A smaller company buying one cloud test may not need the full PTaaS operating model.”
5. Cobalt
Cobalt is a remote-first offensive security company founded in 2013 and led by CEO Sonali Shah. Its headquarters is at 575 Market Street in San Francisco, California, with additional offices in Boston and Berlin. It pioneered a Penetration Testing as a Service model and provides cloud, web, API, network, AI and LLM, red team, code review, and continuous testing services.
Cloud testing covers AWS, Microsoft Azure, Google Cloud, hybrid, and multi-cloud environments through a collaborative platform and vetted pentester community.
Best For
Best suited to SaaS companies, development-focused teams, and enterprises that need cloud tests launched quickly and managed through a collaborative, credit-based platform.

Company Overview
- Company Name: Cobalt Labs, Inc.
- Headquarters: 575 Market Street, San Francisco, California, United States
- Founded: 2013
- Founders: Jacob Hansen, Christian Hansen, Jakob Storm, and Esben Friis Jensen
- CEO: Sonali Shah
- Supported Cloud Platforms: AWS, Microsoft Azure, and Google Cloud Platform
- Customers: 1,500+ customers
- Pentester Community: 400+ Cobalt Core pentesters
- Annual Testing Volume: 5,000+ penetration tests annually
- Core Services: Cloud, web, API, network, AI and LLM penetration testing; red teaming; code review; digital risk assessments
- Delivery Model: Human-led and AI-supported PTaaS platform
- Certifications: SOC 2 Type II, ISO 27001, and CREST penetration-testing accreditation
- Pricing: Custom annual credit packages
Cloud Penetration Testing Capabilities
Cobalt assesses customer-controlled cloud applications, configurations, identities, data, networks, storage, compute, and containers under the shared responsibility model.
Testing follows cloud-native security risks such as weak IAM, exposed storage, poor segmentation, vulnerable workloads, and insecure multi-cloud connections.
Pentesters manually validate exploitability and can combine cloud testing with application, API, network, container, and red team assessments.
Key Features
- Multi-Cloud Testing: Supports AWS, Azure, Google Cloud, hybrid, and multi-cloud environments.
- Manual Exploit Validation: Focuses on weaknesses that can be practically exploited.
- Collaborative Platform: Provides live findings and direct communication with testers.
- Vetted Tester Matching: Assigns specialists based on the cloud platform and technology stack.
- Workflow Integrations: Connects findings to Jira, GitHub, Slack, Azure DevOps, and related tools.
- Unlimited Retesting: Allows repeated validation of corrected findings during the contract term.
Compliance Support
Audit reports, customer letters, and attestations can support SOC 2, ISO 27001, PCI DSS, HIPAA, and related assurance requirements.
Pros
- Supports AWS, Microsoft Azure, and Google Cloud
- Strong fit for recurring cloud and application testing
- Provides real-time tester communication
- Integrates findings into development workflows
- Includes unlimited retesting during the contract term
- Maintains CREST, ISO 27001, and SOC 2 Type II credentials
Limitations
- Annual credits can create utilization risk when planned tests are delayed or cancelled.
- The community tester model means team composition can vary between engagements.
- Hybrid and multi-cloud assessments can consume credits faster than a single-target test.
Pricing
Cobalt sells Standard, Premium, and Enterprise annual credit packages. Credit use depends on target count, cloud complexity, delivery requirements, testing depth, platform features, and support. Contract timing and unused-credit terms should be confirmed before purchase.
Customer Evidence
Cobalt reports 1,500+ customers and 5,000+ penetration tests annually. Customer feedback highlights exploitable findings, direct tester collaboration, and faster testing cycles.
“Cobalt makes more sense for teams that test frequently and can use annual credits consistently. Buyers planning only one or two assessments should compare the credit model against a fixed-scope engagement.”
6. Praetorian
Praetorian is an Austin-based offensive security company founded in 2010 by Nathan Sportsman. It provides cloud, application, network, red team, CI/CD, AI, attack-path, and continuous exposure services.
Cloud testing covers AWS, Microsoft Azure, Google Cloud, Kubernetes, containers, serverless systems, infrastructure as code, and multi-cloud environments, with emphasis on practical attack paths.
Best For
Best suited to security-mature enterprises and cloud-native organizations needing complex IAM, cross-account, Kubernetes, serverless, infrastructure-as-code, CI/CD, or detection testing.

Company Overview
- Company Name: Praetorian Security, Inc.
- Headquarters: Austin, Texas, United States
- Founded: 2010
- Founder and CEO: Nathan Sportsman
- Delivery Presence: Remote-first with employees across multiple countries
- Supported Cloud Platforms: AWS, Microsoft Azure, and Google Cloud Platform
- Other Environments: Kubernetes, containers, serverless systems, hybrid cloud, and multi-cloud
- Core Services: Cloud, application, network, IoT, automotive, and AI penetration testing; red teaming; purple teaming; CI/CD security; attack-path mapping
- Platform: Praetorian Guard
- Delivery Model: Engineer-led point-in-time and continuous offensive security
- Pricing: Custom quote
Cloud Penetration Testing Capabilities
Praetorian begins with architecture interviews and threat modeling. The team then defines testing objectives and tests selected attack scenarios against critical assets and trust relationships.
Assessments cover IAM, federated access, storage, databases, virtual machines, networks, APIs, managed services, secrets, and cloud-to-on-premises connections.
Testing can cover Kubernetes, containers, serverless functions, infrastructure as code, and CI/CD pipelines. Testers look for excessive privileges, exposed credentials, weak isolation, and unsafe deployment trust.
Deliverables document exploitation paths, business risk, technical evidence, strategic recommendations, and immediate critical findings.
Key Features
- Attack-Path Assessment: Maps how separate weaknesses connect to critical assets.
- Objective-Based Testing: Defines clear security goals before exploitation begins.
- Manual Exploitation: Validates whether weaknesses create real access or privilege escalation.
- Multi-Cloud Coverage: Tests AWS, Azure, Google Cloud, hybrid, and distributed environments.
- Praetorian Guard: Supports continuous discovery, validation, vulnerability management, and testing.
- Aurelian: Provides open-source cloud reconnaissance, secrets discovery, and IAM analysis.
Compliance Support
Reports can support SOC 2, ISO 27001, PCI DSS, HIPAA, FedRAMP, NIST, CMMC, and DORA requirements with scope, evidence, findings, and remediation guidance.
Pros
- Long offensive-security track record
- Dedicated AWS, Azure, and Google Cloud testing
- Strong IAM and cross-account attack-path analysis
- Covers Kubernetes, containers, serverless, CI/CD, and infrastructure as code
- Offers point-in-time and continuous testing
- Develops original cloud security tooling
Limitations
- Aurelian has deeper public module coverage for AWS than for Azure or Google Cloud.
- The objective-based attack-path method is not an exhaustive compliance configuration checklist.
- Praetorian Guard requires operational integration beyond a one-time assessment.
Pricing
Praetorian provides custom quotes based on cloud accounts, resources, identities, containers, applications, serverless functions, infrastructure as code, CI/CD systems, objectives, access level, duration, reporting, and continuous-testing needs. Attack-path depth and continuous coverage materially affect the final scope.
Customer Evidence
Praetorian publicly lists major technology, financial, healthcare, media, and industrial organizations, with case studies involving Booking Holdings, Nielsen, OpenTable, Priceline, Samsung, X, and Zoom.
7. TrustedSec
TrustedSec is a Fairlawn, Ohio cybersecurity consultancy founded in 2012 by David Kennedy. It provides cloud, network, application, red team, social engineering, incident response, forensics, hardening, and advisory services.
Dedicated cloud penetration testing focuses on AWS and Microsoft Azure, using external and assumed-access scenarios to test what an attacker could do after compromising an identity, application, developer component, or workload.
Best For
Best suited to enterprises, regulated organizations, government entities, and security-mature companies operating complex AWS, Azure, Microsoft 365, Entra ID, or hybrid identity environments.

Company Overview
- Company Name: TrustedSec, LLC
- Headquarters: Fairlawn, Ohio, United States
- Founded: 2012
- Founder and CEO: David Kennedy
- Dedicated Cloud Testing: AWS and Microsoft Azure
- Additional Cloud Expertise: Microsoft 365, Entra ID, GCP, Alibaba Cloud, and Oracle Cloud hardening
- Core Services: Cloud, network, application, software, hardware and IoT testing; red teaming; social engineering; incident response; digital forensics; hardening and advisory
- Completed Engagements: 7,400+ custom security engagements
- NPS: 92%
- Accreditation: CREST-accredited penetration testing provider
- Delivery Model: Consultant-led, adversary-informed testing
- Pricing: Custom quote
Cloud Penetration Testing Capabilities
TrustedSec can begin from an external perspective. Testing can then continue from an approved assumed-access position that represents a compromised user, application, developer system, or workload.
Assessments cover identities, authentication, permissions, applications, APIs, exposed services, storage, workloads, cloud-to-internal connections, and Microsoft cloud controls.
Cloud testing can extend into social engineering, assumed-breach testing, and internal network access. The engagement can cover developer compromise and remediation validation as well.
Key Features
- Assumed-Access Testing: Evaluates cloud attack paths after an initial identity or workload compromise.
- AWS and Azure Focus: Provides dedicated penetration testing for both platforms.
- Microsoft Identity Expertise: Covers Entra ID, Microsoft 365, Conditional Access, and privileged roles.
- Real-World Attack Simulation: Uses adversary tactics rather than configuration scanning alone.
- Integrated Testing: Combines cloud work with phishing, internal networks, applications, and red teams.
- Remediation Support: Provides prioritized fixes, hardening assistance, and validation testing.
Compliance Support
Testing can support SOC 2, PCI DSS, HIPAA, ISO 27001, NIST SP 800-53, NIST SP 800-171, and CMMC requirements. TrustedSec is a CREST-accredited penetration testing provider.
Pros
- More than a decade of cybersecurity consulting experience
- Dedicated AWS and Azure penetration testing
- Strong Microsoft 365, Entra ID, and Azure identity expertise
- Uses external and assumed-access perspectives
- Combines cloud testing with social engineering and incident response expertise
- Provides remediation guidance and validation testing
Limitations
- Dedicated cloud penetration testing is documented most clearly for AWS and Azure, while Google Cloud is more prominent in hardening services.
- Assumed-access testing requires credential provisioning and coordination with identity and cloud operations teams.
- Microsoft 365 and Entra ID specialization provides less differentiation for Google Cloud-only environments.
Pricing
TrustedSec provides custom quotes based on AWS and Azure scope, Microsoft 365 and Entra ID coverage, identities, applications, access assumptions, cloud-hosted services, social engineering, hybrid connections, compliance needs, and validation testing. Assumed-access and combined identity scenarios require additional coordination and effort.
Customer Evidence
TrustedSec reports 7,400+ custom security engagements and a 92% Net Promoter Score across enterprise, government, financial, healthcare, technology, automotive, and manufacturing clients.
8. Coalfire
Coalfire is a Chicago-based cybersecurity services company founded in 2001. Its portfolio spans cloud security, penetration testing, adversary simulation, compliance assessments, managed security, and cloud engineering.
Offensive testing is delivered through DivisionHex and is closely connected to Coalfire’s experience with FedRAMP, PCI DSS, HIPAA, SOC, ISO, HITRUST, NIST, CMMC, and other frameworks.
Best For
Best suited to large enterprises, SaaS and cloud providers, regulated industries, and government contractors that need cloud penetration testing tied to formal compliance or federal authorization.

Company Overview
- Company Name: Coalfire
- Headquarters: Chicago, Illinois, United States
- Founded: 2001
- CEO: Brad Little
- Offensive Security Practice: DivisionHex
- Company Scale: 1,000+ employees and 1,000+ enterprise clients
- Cloud Coverage: Major public-cloud, SaaS, hybrid, and cloud-native environments
- Core Services: Cloud penetration testing, application testing, red teaming, managed security, and AI security
- Delivery Model: Threat-informed projects and flexible DivisionHex OnDemand engagements
- Pricing: Custom quote
Cloud Penetration Testing Capabilities
DivisionHex tests cloud environments from an attacker’s perspective. Scope can include applications, APIs, identities, workloads, data stores, networks, and cloud-to-on-premises connections.
Assessments can cover IAM, authentication, exposed services, storage, segmentation, application flaws, configuration errors, API authorization, privilege escalation, and attack paths between systems.
Coalfire can connect cloud testing to AWS, Azure, and Google Cloud environments. The work can support FedRAMP authorization boundaries, regulatory assessments, and remediation.
Key Features
- Threat-Informed Testing: Uses human-led attack techniques to validate important weaknesses.
- Cloud and SaaS Experience: Works with major cloud providers, SaaS companies, and regulated enterprises.
- Compliance-Based Testing: Supports FedRAMP, PCI DSS, HIPAA, and related assessment programs.
- Cloud API Testing: Examines authentication, authorization, injection, privilege escalation, and data access.
- Adversary Simulation: Combines cloud testing with red teams, social engineering, and assumed compromise.
- On-Demand Model: Provides flexible scheduling, centralized reporting, and predictable monthly spending.
Compliance Support
Coalfire supports a broad range of security, privacy, and regulatory frameworks, including FedRAMP, PCI DSS, HITRUST, HIPAA, SOC, ISO, CMMC, NIST, and AI-related standards.
Pros
- Long cybersecurity, cloud, and compliance track record
- Large enterprise and compliance assessment practice
- Dedicated offensive security services through DivisionHex
- Strong FedRAMP and regulated-cloud expertise
- Combines cloud, web, API, network, mobile, IoT, hardware, and AI testing
- Connects penetration-test evidence to formal assessments
Limitations
- Assessment-independence boundaries require confirmation when Coalfire provides advisory work and formal assessment services for the same environment.
- Public DivisionHex materials do not provide a detailed platform-by-platform cloud testing matrix.
- DivisionHex is a newer service brand, so its public cloud-specific case library remains limited.
Pricing
Coalfire provides custom quotes based on architecture, systems, applications, APIs, identities, accounts, compliance requirements, objectives, and duration. DivisionHex OnDemand offers fixed monthly invoices and rolling program funds, while project work is scoped separately.
Customer Evidence
Coalfire reports 1,000+ enterprise clients and 1,000+ employees. Its penetration-risk research analyzed 11,000+ penetration tests, nearly 500,000 testing hours, and approximately 20,000 findings across cloud and other attack surfaces.
9. IBM X-Force Red
IBM X-Force Red is IBM’s global offensive security team, established in 2016. Its 200+ hackers provide cloud, application, network, AI, mainframe, hardware, social engineering, adversary simulation, and vulnerability-management services.
Cloud work covers cloud assets, applications, DevOps environments, and hybrid infrastructure, using attacker-led testing, threat intelligence, and project, subscription, or managed delivery models.
Best For
Best suited to large enterprises, financial institutions, governments, healthcare organizations, technology companies, and multinational businesses with complex hybrid-cloud environments.

Company Overview
- Service Name: IBM X-Force Red
- Parent Company: International Business Machines Corporation
- IBM Headquarters: Armonk, New York, United States
- IBM Founded: 1911
- X-Force Red Established: 2016
- IBM CEO: Arvind Krishna
- Team Scale: 200+ hackers worldwide
- Cloud Coverage: Cloud assets, DevOps, and hybrid infrastructure
- Core Services: Cloud, application, network, AI, and hardware penetration testing; adversary simulation; vulnerability management
- Engagement Models: Ad hoc projects, subscription programs, and fully managed testing
- Collaboration Platform: X-Force Red Portal
- Pricing: Custom quote
Cloud Penetration Testing Capabilities
X-Force Red tests cloud environments for practical attack paths. Coverage can include excessive permissions, exposed services, identities, applications, APIs, workloads, databases, and storage.
Engagements can begin externally or from an assumed-breach position. Testers then examine privilege escalation, lateral movement, and access to sensitive systems or data.
DevOps testing examines shared credentials, API and SSH keys, repositories, object storage, and insecure development practices that can expose cloud access.
Key Features
- Global Offensive Team: Supports international offensive-security delivery through IBM.
- Attacker-Led Testing: Manually connects cloud, identity, application, and credential weaknesses.
- Hybrid Coverage: Combines cloud testing with applications, networks, mainframes, hardware, AI, and personnel.
- Threat Intelligence Integration: Draws on IBM researchers, responders, malware analysts, and threat analysts.
- Red Portal: Centralizes milestones, findings, reports, and program status.
- Flexible Delivery: Supports projects, subscriptions, and fully managed testing programs.
Compliance Support
Specialized testing can support PCI DSS, HIPAA, GDPR, DORA TLPT, and TIBER-EU requirements with validated findings, evidence, prioritization, and remediation guidance.
Pros
- Global offensive-security delivery team
- Backed by IBM’s consulting, research, cloud, and security resources
- Tests cloud assets with applications, networks, AI, mainframes, hardware, and personnel
- Strong privilege-escalation and lateral-movement testing
- Integrates threat intelligence and incident-response expertise
- Offers project, subscription, and managed-service models
Limitations
- Public service materials do not provide a granular AWS, Azure, and Google Cloud testing matrix.
- Global programs can require complex procurement and coordination across business units and regions.
- The published backlog-reduction case reflects vulnerability management rather than a cloud penetration test outcome.
Pricing
IBM X-Force Red provides custom pricing based on cloud accounts, applications, workloads, identities, DevOps systems, access assumptions, adversary-simulation goals, geographic delivery, compliance needs, and the selected project, subscription, or managed model. Multi-region coordination and combined offensive services increase program scope.
Customer Evidence
Public examples include Unisys and a global bank where X-Force Red helped achieve a 60% reduction in critical vulnerabilities within four months. This result came from vulnerability-management services rather than a cloud penetration test.
10. Mandiant
Mandiant is a cybersecurity consulting and threat intelligence company founded in 2004 and acquired by Google Cloud in 2022. It provides cloud, application, network, red team, social engineering, incident response, security validation, and cyber-defense services.
Its cloud penetration testing uses techniques informed by frontline investigations and threat intelligence to test cloud resources, applications, identities, configurations, and connected systems.
Best For
Best suited to large enterprises, financial institutions, governments, healthcare providers, critical-infrastructure operators, and multinational organizations that need threat-informed testing across complex cloud or hybrid environments.

Company Overview
- Company Name: Mandiant
- Parent Organization: Google Cloud
- Founded: 2004
- Founder: Kevin Mandia
- Joined Google Cloud: September 2022
- Supported Cloud Platforms: AWS, Microsoft Azure, Google Cloud, and multi-cloud environments
- Core Services: Cloud, application, network, IoT, and ICS penetration testing; red teaming; incident response; threat intelligence
- Delivery Model: Consultant-led, threat-intelligence-informed assessments
- Engagement Options: Individually scoped projects and Mandiant retainer access
- Pricing: Custom quote
Cloud Penetration Testing Capabilities
Mandiant tests whether cloud weaknesses can lead to unauthorized access, privilege escalation, or data exposure. Testing can span applications, APIs, identities, networks, storage, and connected infrastructure.
Consultants perform reconnaissance, enumerate vulnerabilities, select realistic exploitation methods, and attempt agreed objectives such as accessing sensitive data or crossing segmented systems.
A separate Cloud Architecture and Security Assessment can review architecture, monitoring, and detection controls. It can cover scenario exercises and prioritized hardening across AWS, Azure, and Google Cloud.
Key Features
- Frontline Threat Intelligence: Uses knowledge from Mandiant investigations and Google Threat Intelligence.
- Manual Exploitation: Attempts to exploit verified weaknesses with public, commercial, and internal tools.
- Multi-Cloud Coverage: Assesses AWS, Microsoft Azure, Google Cloud, on-premises, and hybrid environments.
- Objective-Based Testing: Targets agreed assets such as PII, payment data, trade secrets, or privileged systems.
- Vulnerability Chaining: Tests whether several weaknesses can form a serious attack path.
- Detection Validation: Combines cloud testing with red or purple teams to evaluate security operations.
Compliance Support
Validated findings and technical evidence can support PCI DSS, HIPAA, GDPR, DORA TLPT, TIBER-EU, and internal risk-management requirements, subject to the agreed engagement scope.
Pros
- Long cybersecurity and incident-response track record
- Part of Google Cloud since 2022
- Supports AWS, Microsoft Azure, and Google Cloud
- Uses intelligence from current breach investigations
- Combines cloud testing with applications, networks, social engineering, IoT, ICS, and incident response
- Strong privilege-escalation, lateral-movement, and detection testing
Limitations
- Active cloud penetration testing and the Cloud Architecture and Security Assessment are separate scopes.
- Mandiant does not present a self-service PTaaS platform with public credit packages.
- Combining testing, red teaming, incident response, and long-term advisory work can require a retainer or additional scope.
Pricing
Mandiant provides custom quotes based on cloud projects, applications, APIs, identities, access assumptions, cloud-to-on-premises connections, objectives, red or purple team components, reporting, retesting, geography, regulation, and project or retainer delivery. Architecture assessment, active exploitation, and operational validation should be priced as distinct scope components.
Customer Evidence
Mandiant highlights Lloyds Banking Group and publishes case examples showing how exposed keys, application flaws, limited access, and vulnerability chains can lead to sensitive systems or documents.
“We would consider Mandiant when threat intelligence, incident response experience, and complex hybrid-cloud testing carry more weight than transparent pricing or self-service test management.”
How Should a Company Choose a Cloud Penetration Testing Company?
Choosing a cloud penetration testing company requires verifying that the firm tests cloud infrastructure rather than the applications running on top of it. Cloud environments fail through identity misconfiguration, over-permissioned roles, and exposed storage far more often than through application code defects. The right vendor proves cloud-specific skill, names its testers, and scopes to a stated level of access.
A qualified firm maps privilege escalation paths between accounts, reviews identity and access management policy, examines the container and serverless surface, and delivers findings that name the exact resource at fault.
The following criteria separate cloud penetration testing firms from application testing firms selling the same engagement under a newer name.

1. Confirm They Test the Cloud Control Plane
Ask the firm to describe what it touches inside your cloud account. Cloud penetration testing covers identity and access management policy, role trust relationships, instance metadata access, storage permissions, key management, logging gaps, and privilege escalation paths across accounts. Web application testing covers input validation, authentication logic, and session handling within one application. The two engagements share a category name and little else. Request a scope document listing the specific cloud services in range before you accept any proposal.
Firms that answer this question with scanner output are selling a configuration review.
Bright Defense performs penetration testing in-house and tests cloud infrastructure alongside the application layer.
2. Check the Credentials of the Testers Assigned to Your Account
Ask for names and titles in writing. The credentials worth looking for are OSCP, GIAC Cloud Penetration Tester, AWS Certified Security Specialty, and Azure AZ-500, since each one covers offensive work or provider-specific security architecture rather than general IT experience. Follow the credential question with a second one: how many hours has this tester spent working in the provider my workloads run on. A tester fluent in AWS identity policy does not automatically read Azure role assignments well.
Firm-level certification pages tell you nothing about who logs into your account on Monday morning.
Bright Defense is led by Tim Mektrakarn, our Co-Founder and CEO, who holds CISSP, CISA, and ISO 27001 Lead Auditor credentials. Tim ran the security program at VPLS through its own SOC 2 and HIPAA work before the company sold to Evocative in 2019. Our Co-Founder John Minnix brings more than twenty years across managed services and compliance.
3. Ask Which Provider Rules of Engagement They Work Under
Every major cloud provider publishes terms governing security testing on its platform, and a firm that has worked in your provider can state them without looking. AWS permits customer-initiated testing against a defined list of services with no advance approval, while prohibiting denial of service simulation, port flooding, and DNS zone walking without written authorization. Microsoft removed its pre-approval requirement for Azure testing and publishes rules of engagement in its place. Google Cloud requires no notification and holds testing to its acceptable use policy.
Testing outside those rules risks account suspension in the middle of your engagement.
Bright Defense scopes every cloud test against the provider’s published testing terms and documents the permitted activity list in the engagement letter.
4. Decide the Level of Access Before You Compare Prices
Access level drives both the price and the value of a cloud penetration test, and three levels are common:
- External only: The tester works from the internet with no credentials. Findings cover exposed services, public storage, and certificate problems.
- Read-only role: The tester holds an audit role across the environment. Findings cover misconfigured trust policies, over-permissioned roles, unencrypted data stores, and logging gaps.
- Foothold simulation: The tester holds one low-privilege credential set and attempts escalation. Findings cover the escalation paths a real intruder would walk after a phished developer account.
Most of the value sits in the second and third levels, because an unauthenticated cloud test returns a list of your external attack surface and stops there. Two quotes that differ by thousands of dollars often differ in access level rather than in skill.
A quote that never mentions credentials is priced for an external scan.
Bright Defense recommends a read-only role plus a foothold credential set for first-time cloud tests, then narrows the access model on repeat engagements.
5. Read a Redacted Sample Report Before You Sign
Ask for a redacted report from a past cloud engagement. A usable finding names the affected account and resource identifier, the policy or role at fault, the reproduction steps, the escalation path it opens, and a fix written in provider terms such as a corrected policy document. Severity ratings should reflect exploitability inside your environment rather than a generic score. Read the executive summary as well, since your auditors and your largest customers will read that page and nothing else.
Reports that stop at a vulnerability list leave your engineers to redo the analysis.
Bright Defense delivers findings with the affected resource named and the remediation path written out.
6. Get the Timeline and the Retest in Writing
Cloud penetration testing timelines depend on account count and workload complexity. Scoping takes about one week. Testing runs one to two weeks for a single-account environment and three to four weeks for a multi-account organization carrying containers and a build pipeline. Reporting adds another week. Remediation sits on your side of the line, and the retest follows once your team closes the findings. Plan for six to eight weeks between kickoff and a clean report.
Confirm the retest appears in the contract with a price attached, whether that price is zero or otherwise. A firm that leaves the retest out expects to invoice you for it later.
Bring your customer or audit deadline to the first call and ask the firm to work backward from it on paper.
7. Ask What Sits Outside the Quote
Cloud testing quotes vary in what they exclude, and the exclusions cost real money. Ask whether the number covers the retest, the Kubernetes and container layer, the CI/CD pipeline, infrastructure-as-code review, connected SaaS integrations, social engineering, and the attestation letter your auditors and customers will request. Compliance requirements pull several of these into scope on their own: SOC 2 and ISO 27001 auditors expect a recent penetration test, and PCI DSS 4.0 requires internal and external testing on an annual schedule.
Get every line item on one page before you compare two proposals.
Bright Defense performs penetration testing in-house and includes compliance automation in our monthly engagement, which keeps testing and continuous monitoring on a single invoice.
Questions to Ask Before You Sign
| Question | Strong Answer | Warning Sign |
| What do you test inside my cloud account? | Named services, identity policy, role trust relationships, storage, and escalation paths | Scanner output and a service list with no detail |
| Who tests my environment, and what do they hold? | Named testers with OSCP, GIAC Cloud Penetration Tester, or provider security certification | Company-level credential claims with no names |
| Which provider rules of engagement apply to us? | A direct answer covering permitted and prohibited testing activity | A promise to look it up before kickoff |
| What access will your testers hold? | A stated level, from external only to read-only role to foothold credentials | A price with no mention of credentials |
| What does a finding look like in your report? | Resource identifiers, reproduction steps, escalation paths, and provider-native fixes | A generic vulnerability list with CVSS scores |
| How long until I hold a report? | A dated plan covering scoping, testing, reporting, and retest | One week for a multi-account environment |
| What falls outside this quote? | Retest, container scope, pipeline review, and attestation letter broken out | A single number with no breakdown |
Cloud Provider Testing Rules To Confirm Before Scoping
Cloud penetration testing must stay within the customer-authorized scope. Testing must follow the current policy of the cloud provider. The written scope should list the accounts, subscriptions, projects, tenants, and workloads under test. It should state source addresses, testing windows, contacts, and stop conditions.

1. AWS
AWS permits customers to test listed customer-controlled services without prior approval, including common EC2, RDS, CloudFront, API Gateway, Lambda, ECS, Fargate, OpenSearch, FSx, and Transit Gateway resources. Testing AWS infrastructure or AWS services themselves is prohibited. Route 53 zone walking, DNS hijacking or pharming, denial-of-service activity, request or protocol flooding, S3 bucket takeover, and subdomain takeover are prohibited. Command-and-control testing and other special simulations require prior approval.
2. Microsoft Azure
Microsoft’s rules allow authorized testing of resources the customer owns or has explicit permission to test. Testing unowned tenants, storage, data, credentials, or customer systems is prohibited. Denial-of-service activity, excessive traffic, network-intensive fuzzing, phishing through Microsoft services, and post-exploit actions beyond the initial proof of concept, including lateral movement and pivoting, are prohibited.
3. Google Cloud
Google Cloud’s Acceptable Use Policy prohibits unauthorized access, disruption, impairment, service interference, destructive code, phishing, and attempts to bypass service controls. Customer-owned workloads may be tested only within the organization’s authorization and contractual boundary. Testing Google-managed services or infrastructure requires an express basis in the applicable agreement or program.
4. Shared Responsibility Boundary
The normal assessment scope covers customer-controlled data, identities, configurations, applications, and workloads. Customers generally cannot test provider-managed infrastructure. That boundary includes physical facilities, hardware, foundational networks, hypervisors, and managed-service internals. The division varies by service model under the AWS model, Azure model, and Google Cloud model.
What Determines Cloud Penetration Testing Cost
Cloud penetration testing cost is driven by the authorized attack surface and required testing depth rather than the cloud provider name alone.
- Account Count: More AWS accounts, Azure subscriptions, Google Cloud projects, and connected organizations create additional trust relationships and configuration paths to test.
- IAM Object Volume: Users, groups, roles, service accounts, policies, permission boundaries, federated identities, and cross-account trusts increase enumeration and privilege-escalation work.
- Kubernetes And Container Scope: Clusters, namespaces, service accounts, registries, images, admission controls, workload identities, secrets, and control-plane relationships add specialized testing tasks.
- Application And API Count: Each cloud-hosted application, API, gateway, function, and business workflow expands authentication, authorization, input-validation, and business-logic coverage.
- Access Model: Assumed-access testing requires provisioned identities and post-compromise analysis, while external-only testing centers on internet-visible assets and exposed entry points. The same split between internal and external penetration testing governs which credentials and network positions the engagement covers.
- Retesting: Retesting adds time for validating fixes, checking regression risk, and updating the final report or attestation.
Bright Defense’s penetration testing pricing guide provides broader pricing context for scoping a project.
Final Thoughts
The best cloud penetration testing company depends on the environment being tested. Cloud platforms, identity design, workload types, assurance requirements, and testing frequency should guide the selection.
Buyers should compare the provider’s documented platform coverage, manual exploitation depth, cloud-policy process, reporting, remediation support, and retesting terms before signing an engagement.
A narrow annual test requires a different scope from a multi-account attack-path assessment. The provider, testing effort, and budget may differ as well.
Reviewing what a penetration testing report should contain gives procurement teams a fixed standard to score sample deliverables against.
Cloud Penetration Testing FAQ
What Is Cloud Penetration Testing
Cloud penetration testing is an authorized security assessment that tests customer-controlled cloud identities, configurations, workloads, applications, APIs, storage, networks, and attack paths for exploitable weaknesses.
What Is Included In A Cloud Penetration Test
A cloud penetration test typically includes scope validation, asset and identity enumeration, configuration review, manual exploitation, privilege-escalation analysis, evidence collection, risk reporting, remediation guidance, and retesting when contracted.
How Much Does Cloud Penetration Testing Cost
Cloud penetration testing cost depends on account count, IAM object volume, applications and APIs, Kubernetes and container coverage, access model, testing objectives, reporting requirements, and retesting.
Do You Need Permission To Penetration Test AWS
AWS permits testing of listed customer-controlled services without prior approval, while prohibited activities and special simulations remain subject to AWS policy and approval requirements.
Can You Penetration Test Azure Without Prior Approval
Authorized Azure resources can be tested under Microsoft’s rules, while unowned systems, denial-of-service activity, excessive traffic, phishing, and post-exploit lateral movement remain prohibited.
Does Google Cloud Allow Penetration Testing
Google Cloud permits customer-authorized security work only within the contractual and acceptable-use boundary, while unauthorized access, disruption, service interference, phishing, and testing of Google-managed systems remain prohibited.
How Often Should Cloud Penetration Testing Be Performed
Cloud penetration testing should be performed at least annually and after material changes such as new accounts, identity redesigns, major releases, Kubernetes deployments, acquisitions, or significant architecture changes.
Related Reads


